Wireless and Other Attack Surfaces
CAP, ACID vs BASE, latency numbers, back-of-envelope estimation, single points of failure — the vocabulary every system designer thinks in.
Core Philosophy: Attacks don’t only travel over cables and through web forms. They travel through the air, through physical doors, and through the growing crowd of connected devices that were never designed with security in mind. This page broadens your awareness beyond the wired network and the web — because a serious assessment, and a serious defender, must account for every way in, not just the obvious ones.
Part 1: The Problem
Phases 2 and 3 so far have focused on web applications and wired network infrastructure — rightly, because that’s where the bulk of practical security work lives. But an organization’s true attack surface (0.4) is wider:
- Its networks extend through the air as Wi-Fi — and radio waves don’t stop at the office walls.
- Its premises have physical entry points, and physical access often defeats digital controls entirely.
- It increasingly runs connected devices — cameras, sensors, smart equipment, industrial controllers — many built with security as an afterthought, if at all.
A complete picture of security has to include these. This page is deliberately awareness-level: the goal is for you to understand these attack surfaces exist, how they’re approached, and why they matter — not to make you a wireless or hardware specialist (each is its own deep field). It rounds out your map of where attacks come from before Phase 4 turns to defense.
Part 2: Wireless — The Network That Leaves the Building
Wi-Fi extends a network into the air around it. That convenience is also the security problem: unlike a wired network, where an attacker needs physical access to a cable, a wireless network can be reached by anyone within radio range — the car park, the street, the building next door. The network’s edge is no longer the wall.
What an attacker can attempt against wireless, conceptually:
- Eavesdropping. Wireless traffic travels through the air; an attacker in range can capture it. This is exactly why wireless encryption matters — and why the strength of that encryption matters. Older Wi-Fi security standards have known, serious weaknesses; current standards are far stronger. A network using an outdated wireless security standard is exposed.
- Attacking the wireless password/key. Depending on the security standard in use, attackers may attempt to capture the data needed to crack the network’s password offline — which is, again, a password-strength problem (the recurring 2.6 / 1.3 theme: weak passwords fall).
- Rogue access points and “evil twin” attacks. An attacker sets up a malicious Wi-Fi access point impersonating a legitimate one. Users’ devices connect to the attacker’s network, placing the attacker in the middle of their traffic (a wireless man-in-the-middle, conceptually related to the position TLS in 1.3 exists to defend against).
- Guest and segmentation issues. A wireless network that isn’t properly segmented (4.3/4.4) from sensitive internal systems can let someone who gets onto the Wi-Fi reach far more than they should.
The defensive themes are ones you already hold: use strong, current wireless encryption standards; strong wireless passwords; segment wireless networks from sensitive systems; and be aware that the network extends physically beyond the walls.
⚖️ Wireless testing has a sharp legal edge: capturing wireless traffic and attacking Wi-Fi networks is interacting with networks — almost always other people’s — and is regulated by law. Practice only on your own wireless network, or with explicit authorization. Wireless testing also often needs specific hardware, which is why this page’s lab is optional and strictly self-targeted.
Part 3: Physical Security — Where Digital Defenses End
Security is not only digital. Physical security — control over physical access to premises, machines, and equipment — underlies all of it, and is easy to forget.
The core principle: physical access often beats digital defenses. If an attacker can physically reach a machine, many software protections weaken or fall — they may be able to access its storage directly, plug in a malicious device, reset credentials, or simply take it. A server with perfect software hardening is not secure if anyone can walk up to it.
Awareness-level points:
- Physical entry to a building or a server area is itself a serious compromise vector. Locks, access controls, and monitoring of physical spaces are genuine security controls.
- Unattended machines — an unlocked, logged-in computer is an open door for anyone who passes it.
- Physical media and devices — a malicious USB device, a discarded hard drive with readable data, a sticky note with a password. Small physical things carry real risk.
- This connects to social engineering (Part 4) — physical intrusion often combines with talking one’s way past people.
For defenders, the lesson is that a security program that secures only the digital and ignores the physical has a gap — and a complete threat model (1.2) includes physical attack paths.
Part 4: IoT and the Human Attack Surface
Two more pieces complete the picture.
IoT — the Internet of Things. Organizations and homes increasingly run large numbers of connected devices — cameras, sensors, smart appliances, building systems, medical and industrial equipment. As a security matter, IoT devices are frequently weak: many are built cheaply with security as an afterthought, ship with default credentials (2.9), run outdated software that’s rarely or never patched (2.10), and expose unnecessary services (0.4). Yet they sit on real networks. A weak connected device can be an attacker’s entry point onto a network, or a target in itself. The vulnerability classes are ones you already know — defaults, outdated software, exposed services, weak authentication — appearing in a new category of device. (Industrial and operational-technology environments raise the stakes further, since there compromise can affect physical processes — a serious specialized field of its own.)
The human attack surface — social engineering. The most important attack surface of all is often not technical: it’s people. Social engineering is manipulating people into taking actions or revealing information that compromise security — and it is one of the most effective attack methods that exists, because it sidesteps technical defenses entirely. Phishing (which you met in 2.6 as a route to credentials) is the most common form: deceptive messages tricking people into revealing credentials or running malicious content. Other forms include pretexting (inventing a convincing scenario), impersonation, and baiting. The defenses are necessarily different — security awareness and training, a culture where people can question and verify, processes that don’t rely on a single person’s judgment, and technical controls (like MFA, 1.4) that limit the damage when someone is fooled. Phase 6.9 returns to social engineering specifically, because AI is making it dramatically more convincing and scalable.
Part 5: Putting the Full Attack Surface Together
Step back, and the picture from 0.4 — attack surface — is now complete. An organization’s real attack surface is everything across these dimensions:
THE COMPLETE ATTACK SURFACE
┌─────────────────────────────────────────────┐
│ Web applications (Phase 2) │
│ Network services & infra (Phase 3.1–3.3) │
│ Internal AD environment (Phase 3.5) │
│ Wireless networks (this page) │
│ Physical access (this page) │
│ Connected / IoT devices (this page) │
│ People (social engineering) (this page) │
└─────────────────────────────────────────────┘
An attacker needs ONE of these to work.
A defender must account for ALL of them.
This is the defender’s fundamental challenge restated (it first appeared in 1.2): the attacker needs only one way in; the defender must cover every one. A security program focused only on web and wired networks, ignoring wireless, physical, IoT, and people, has real and exploitable gaps.
This breadth is also why threat modeling (1.2) matters so much — it’s the disciplined way to make sure every relevant attack surface is considered, not just the familiar ones. And it’s why “cybersecurity” is so many specializations (1.5): each of these surfaces is deep enough to be a career. You don’t master them all — but as a competent generalist you must know they exist and account for them. That awareness is what this page provides.
Part 6: The Defense — A Preview of Phase 4
The offense/defense mirror, across this page’s broader surfaces. These defenses are part of Phase 4’s hardening (4.4) and secure design (4.3), and the human side connects to 4.5’s operations:
- Wireless: strong, current encryption standards; strong wireless passwords; segmentation of wireless from sensitive systems; awareness that the network extends beyond the walls; watching for rogue access points.
- Physical: physical access controls (locks, controlled entry, monitoring of sensitive areas); locking unattended machines; protecting physical media; treating physical security as a genuine, threat-modeled part of the program.
- IoT / connected devices: the familiar fixes in a new context — change defaults, patch and update, disable unneeded services, segment IoT devices onto separate networks so a weak device can’t reach sensitive systems, and inventory them (you can’t protect devices you forgot you have — the recurring 2.1 / 3.1 theme).
- People: security awareness and training; a culture where verifying and questioning is encouraged; processes resilient to a single person being deceived; and technical controls (MFA above all) that limit the damage when someone is fooled — because someone, eventually, will be.
- Across all of it: defense in depth (1.1) and comprehensive threat modeling (1.2), so every attack surface — not just the obvious ones — is accounted for.
🔑 The deep lesson: the attack surface is wider than the keyboard. Wireless carries the network into the air, physical access can defeat digital controls outright, connected devices add weak nodes to real networks, and people remain the most reliably exploitable surface of all. A defender — and a complete assessment — has to see all of it.
📓 Key Terms
| Term | Plain meaning |
|---|---|
| Wi-Fi / wireless | A network that extends over radio rather than cables. |
| Wireless encryption standard | The scheme protecting Wi-Fi traffic; older ones have known weaknesses. |
| Rogue access point / evil twin | A malicious Wi-Fi access point impersonating a legitimate one. |
| Physical security | Control over physical access to premises, machines, and equipment. |
| IoT | The Internet of Things — networked everyday/industrial devices. |
| Social engineering | Manipulating people into compromising security. |
| Phishing | Deceptive messages tricking people into revealing info or running malicious content. |
| Attack surface | The complete set of all points an attacker could target. |
🧪 Hands-On Lab
Wireless tasks: your own Wi-Fi network only. Capturing wireless traffic or attacking networks you don’t own is regulated by law and requires authorization. Most of this page’s labs are observational and conceptual by design.
Task 1 — Inspect your own wireless network. Look at your own home Wi-Fi’s settings: which security/encryption standard is it using? Is it a current, strong one? Is the password strong? Is there a guest network, and is it separated from your main network? You’re assessing your own wireless attack surface.
Task 2 — Understand wireless attacks (reading). Read a reputable overview of how Wi-Fi attacks work — eavesdropping, password cracking, evil-twin attacks. Understand the concepts; you don’t need to perform them. Note the role of strong encryption and strong passwords throughout.
Task 3 — Threat-model the physical. For a space you know (your home, an office you’ve worked in), do a quick physical threat model (using 1.2’s method): what physical attack paths exist? Unattended machines? Accessible equipment? It’s a revealing exercise.
Task 4 — Inventory connected devices. List the connected/IoT devices on a network you own — smart devices, cameras, anything networked. For each, ask: does it still have default credentials? Is its software updated? Does it need to be on the same network as your sensitive devices? This is IoT attack-surface thinking.
Task 5 — Study a social engineering example. Find a reputable breakdown of a real-world phishing or social engineering attack. Identify the manipulation technique used and what defense (awareness, process, MFA) would have blunted it. This sets up Phase 6.9.
Task 6 — Complete your attack surface map. Return to the attack surface diagram in Part 5. For an organization (real or imagined), write out every attack surface dimension and a sentence on how you’d assess each. This is your complete mental model of “where attacks come from” — carry it into Phase 4.
⚠️ Common Mistakes
- Testing wireless on networks you don’t own. Capturing Wi-Fi traffic and attacking wireless networks is regulated by law. Your own network or explicit authorization only.
- Ignoring physical security as “not cybersecurity.” Physical access can defeat digital defenses outright. A complete security program and threat model includes the physical.
- Treating IoT devices as harmless. Weak connected devices with default credentials and outdated software are real network entry points. They count as attack surface.
- Underestimating social engineering. People are the most reliably exploitable attack surface — social engineering bypasses technical defenses entirely. It is not a footnote.
- Thinking security is only web and wired networks. That leaves wireless, physical, IoT, and human gaps wide open. The attacker needs only one.
- Expecting depth from an awareness page. Wireless, hardware, and physical security are each deep specializations. This page builds awareness and a complete map — depth is for later, if you choose those paths.
✅ Recap & What’s Next
- The real attack surface extends beyond web and wired networks: wireless carries the network into the air, physical access can defeat digital controls, IoT adds weak networked devices, and people are the most reliably exploitable surface of all.
- The vulnerability classes are familiar — weak encryption, default credentials, outdated software, exposed services — appearing in new contexts; the defender must account for every surface while the attacker needs only one.
- Defenses (Phase 4) extend the familiar themes — strong encryption, hardening, segmentation, inventory, and, for people, awareness and training plus damage-limiting controls like MFA — all guided by comprehensive threat modeling.
Next (3.7): Phase 3 closes not with a new attack, but with a practice habit. Page 3.7 covers Capture The Flag and structured practice platforms — how to turn everything you’ve learned into a skill that keeps growing, legally and forever.
⁂ Back to all modules